Where does your password actually go?

server.py prints exactly one line per login attempt — whatever request body actually arrives. What's in that body is entirely up to which mode the client uses. Pick a login, flip the mode, and read the server's own log for yourself — real SHA-256 and real HMAC-SHA256, the same primitives common.py uses, computed live in your browser.

Mode — which docker-compose file would be running:

What the client actually sends, and the server's own log line for it:

What was computed (real SHA-256 + real HMAC-SHA256 — common.py's exact construction, nothing scripted):

Log reader — anyone who can read server.py's own print() output

A compromised server, an over-eager third-party logging SaaS, or anyone who later breaches the log store — not a network eavesdropper. TLS never touches this.

Replay attempt

The same log reader, trying to log in again using only what they just captured — no new access, nothing extra.